Personal computing discussed

Moderators: renee, SecretSquirrel, notfred

 
|FN|Steel
Minister of Gerbil Affairs
Topic Author
Posts: 2172
Joined: Wed Dec 26, 2001 7:00 pm
Location: Kansas

Where is a Gmail Account Logged In

Tue Jul 19, 2016 2:14 pm

Guys... any idea how to tell who's logged into a gmail account on a network where the end users aren't on a domain?

I'm posting this in Linux because I have an EdgeRouter by Ubiquiti and it's running a Vyatta fork on a Debian base. So thought MAYBE someone might be able to help from the angle. Thanks!
Sucking down the easy flowing milk from society's warm breasts.
 
chuckula
Minister of Gerbil Affairs
Posts: 2109
Joined: Wed Jan 23, 2008 9:18 pm
Location: Probably where I don't belong.

Re: Where is a Gmail Account Logged In

Tue Jul 19, 2016 2:22 pm

As in who is using a particular gmail account or just identifying traffic that's going to gmail servers [which is all HTTPS anyway]?
4770K @ 4.7 GHz; 32GB DDR3-2133; Officially RX-560... that's right AMD you shills!; 512GB 840 Pro (2x); Fractal Define XL-R2; NZXT Kraken-X60
--Many thanks to the TR Forum for advice in getting it built.
 
|FN|Steel
Minister of Gerbil Affairs
Topic Author
Posts: 2172
Joined: Wed Dec 26, 2001 7:00 pm
Location: Kansas

Re: Where is a Gmail Account Logged In

Tue Jul 19, 2016 2:37 pm

The first. Attach an IP/MAC to a gmail user.
Sucking down the easy flowing milk from society's warm breasts.
 
localhostrulez
Minister of Gerbil Affairs
Posts: 2481
Joined: Sun Mar 09, 2014 11:26 pm

Re: Where is a Gmail Account Logged In

Tue Jul 19, 2016 2:52 pm

I'm confused - if you're sniffing network traffic, it's encrypted, and probably a no-go.

If you're logged into the account and want to see who else is logged into that same account, doesn't Google already have something for that? https://support.google.com/mail/answer/45938?hl=en
 
|FN|Steel
Minister of Gerbil Affairs
Topic Author
Posts: 2172
Joined: Wed Dec 26, 2001 7:00 pm
Location: Kansas

Re: Where is a Gmail Account Logged In

Tue Jul 19, 2016 3:10 pm

Yeah, this would be sniffing. I was hoping SOME part of it was plaintext, but I realize that's way too hopeful.
Sucking down the easy flowing milk from society's warm breasts.
 
SuperSpy
Minister of Gerbil Affairs
Posts: 2403
Joined: Thu Sep 12, 2002 9:34 pm
Location: TR Forums

Re: Where is a Gmail Account Logged In

Tue Jul 19, 2016 3:29 pm

Yeah the entire session is encrypted, so the best you're going to do is see which LAN machines are accessing gmail.com.
Desktop: i7-4790K @4.8 GHz | 32 GB | EVGA Gefore 1060 | Windows 10 x64
Laptop: MacBook Pro 2017 2.9GHz | 16 GB | Radeon Pro 560
 
just brew it!
Administrator
Posts: 54500
Joined: Tue Aug 20, 2002 10:51 pm
Location: Somewhere, having a beer

Re: Where is a Gmail Account Logged In

Tue Jul 19, 2016 3:45 pm

SuperSpy wrote:
Yeah the entire session is encrypted, so the best you're going to do is see which LAN machines are accessing gmail.com.

The only way you could conceivably do this is by installing something like a Blue Coat web proxy between the internal network and the internet, and requiring all users on the network to use browsers which have been pre-configured with the proxy's security certificate (to prevent the users from getting security certificate warnings). This is how corporate IT departments that want to spy on all network usage of their employees do it.

As SuperSpy notes, without the ability to peer into the HTTPS packets the most you'll be able to do is identify which internal MAC/IP addresses are accessing Gmail.
Nostalgia isn't what it used to be.
 
|FN|Steel
Minister of Gerbil Affairs
Topic Author
Posts: 2172
Joined: Wed Dec 26, 2001 7:00 pm
Location: Kansas

Re: Where is a Gmail Account Logged In

Tue Jul 19, 2016 4:22 pm

Yeah, I was reading up on using a certificate proxy. NOT going there. Screw that.
Sucking down the easy flowing milk from society's warm breasts.
 
DancinJack
Maximum Gerbil
Posts: 4494
Joined: Sat Nov 25, 2006 3:21 pm
Location: Kansas

Re: Where is a Gmail Account Logged In

Tue Jul 19, 2016 4:26 pm

|FN|Steel wrote:
Yeah, this would be sniffing. I was hoping SOME part of it was plaintext, but I realize that's way too hopeful.


I don't hope that, and you shouldn't either.
i7 6700K - Z170 - 16GiB DDR4 - GTX 1080 - 512GB SSD - 256GB SSD - 500GB SSD - 3TB HDD- 27" IPS G-sync - Win10 Pro x64 - Ubuntu/Mint x64 :: 2015 13" rMBP Sierra :: Canon EOS 80D/Sony RX100
 
|FN|Steel
Minister of Gerbil Affairs
Topic Author
Posts: 2172
Joined: Wed Dec 26, 2001 7:00 pm
Location: Kansas

Re: Where is a Gmail Account Logged In

Tue Jul 19, 2016 4:54 pm

DancinJack wrote:
|FN|Steel wrote:
Yeah, this would be sniffing. I was hoping SOME part of it was plaintext, but I realize that's way too hopeful.


I don't hope that, and you shouldn't either.


Only in the context of THIS situation, but yeah, I understand.

We had a disgruntled employee setup a gmail account and send an e-mail to everyone in the company from it. I'd love to be able to nail the ****.
Sucking down the easy flowing milk from society's warm breasts.
 
PhilipMcc
Gerbil First Class
Posts: 140
Joined: Thu Feb 05, 2009 10:15 am
Location: Pittsburgh

Re: Where is a Gmail Account Logged In

Wed Jul 20, 2016 7:18 am

This may not be practical if there are many employees or if bcc was used - are you able to parse the To list and see who was not included? Or look in the inboxes that corporate does control?
 
tanker27
Gerbil Khan
Posts: 9444
Joined: Tue Feb 26, 2002 7:00 pm
Location: Georgia

Re: Where is a Gmail Account Logged In

Wed Jul 20, 2016 7:29 am

JBI beat me to it. Blue Coat is the way to go. Blue Coat can also block access to gmail.
(\_/)
(O.o)
(''')(''')
Watch out for evil Terra-Tron; He Does not like you!
 
just brew it!
Administrator
Posts: 54500
Joined: Tue Aug 20, 2002 10:51 pm
Location: Somewhere, having a beer

Re: Where is a Gmail Account Logged In

Wed Jul 20, 2016 7:56 am

tanker27 wrote:
JBI beat me to it. Blue Coat is the way to go. Blue Coat can also block access to gmail.

I should add, I am not a fan of this sort of thing, and my mentioning it should not be considered an endorsement. It creates a huge potential single point of security failure, which can compromise all HTTPS traffic in/out of a network. Furthermore, for organizations which do software development, it causes problems for people who may have a legitimate need to run OSes or browsers other than the ones pre-configured by IT.
Nostalgia isn't what it used to be.
 
tanker27
Gerbil Khan
Posts: 9444
Joined: Tue Feb 26, 2002 7:00 pm
Location: Georgia

Re: Where is a Gmail Account Logged In

Wed Jul 20, 2016 8:16 am

just brew it! wrote:
tanker27 wrote:
JBI beat me to it. Blue Coat is the way to go. Blue Coat can also block access to gmail.

I should add, I am not a fan of this sort of thing, and my mentioning it should not be considered an endorsement. It creates a huge potential single point of security failure, which can compromise all HTTPS traffic in/out of a network. Furthermore, for organizations which do software development, it causes problems for people who may have a legitimate need to run OSes or browsers other than the ones pre-configured by IT.


Yeah I'm not a fan. It was painful when first implemented here. A lot of things were blocked that I use on a daily basis (I am in Software development). And I got tired of my emails back an forth trying to (Nazi IT Sec) get things whitelisted. However, since then they've built an autonomous whitelist workflow/feature where my manager signs off and I get instant access. It's really not so bad now. It blocks a lot; social media/network, cloud based email (gmail Yahoo, et al), of course nsfw websites, youtube, etc. etc.

Personally I have exception to Social stuff and Youtube because of what I do I need the access.
(\_/)
(O.o)
(''')(''')
Watch out for evil Terra-Tron; He Does not like you!
 
localhostrulez
Minister of Gerbil Affairs
Posts: 2481
Joined: Sun Mar 09, 2014 11:26 pm

Re: Where is a Gmail Account Logged In

Wed Jul 20, 2016 9:11 am

tanker27 wrote:
Personally I have exception to Social stuff and Youtube because of what I do I need the access.

Been there, done that. My middle school blocked youtube - and the teachers complained because there are instructional videos on there.

Personally, I keep stuff like Facebook or forums off the corporate computer. I usually have my phone and/or laptop with me anyway.
 
|FN|Steel
Minister of Gerbil Affairs
Topic Author
Posts: 2172
Joined: Wed Dec 26, 2001 7:00 pm
Location: Kansas

Re: Where is a Gmail Account Logged In

Wed Jul 20, 2016 9:43 am

Small company in charge of it all is rather nice. I have access to all the things and know exactly what's being used to track things accessed (nothing)!

I managed to figure out who it was. We're small enough that the suspect list was relegated to a small clique of employees. One of those employees had cleared their web history, gmails, and Skype history right around the same time the email was sent. Circumstantial for sure. So I pulled chat logs from someone they talked to regularly and in that conversation they used almost exactly the same phrase used in the email that got sent out and it was specific enough that there's no chance it was a coincidence.

Next up, internal IM replacement! Anyone have any experience with Openfire? :D
Sucking down the easy flowing milk from society's warm breasts.
 
cheesyking
Minister of Gerbil Affairs
Posts: 2756
Joined: Sun Jan 25, 2004 7:52 am
Location: That London (or so I'm told)
Contact:

Re: Where is a Gmail Account Logged In

Wed Jul 20, 2016 9:53 am

Was just going to suggest that if you start doing a password reset on the account in question and the miscreant added their mobile number to the account Google will tell you the last 3 digits of their number which might have been enough for you to finger them. Probably wouldn't have worked since you'd have to be really stupid to do that under these circumstances.
Fernando!
Your mother ate my dog!

Who is online

Users browsing this forum: No registered users and 19 guests
GZIP: On